Product Screenshots Features Security & Governance Contact Sign in Request a demo
Self-hosted · Provider-agnostic · Approval-gated

Essential Deck
Enterprise AI Orchestration & Governance

The control plane that sits between your people, your data, and every LLM you run — so every chat, query, dashboard, and autonomous agent stays inside the boundaries your governance team sets.

  • Govern every AI interaction.
  • Connect any LLM.
  • Protect sensitive data.
  • Audit every prompt.
  • Generate trusted dashboards.
Architecture

What stays inside your network — and what has to ask permission

Local LLMs, your databases, and your knowledge bases never leave your environment. Public LLM APIs and external signal sources are reached deliberately, through one governed gate — not the default path.

Your network

DMZ

Every connection here is individually classified, Confidential and Secret included — none of it is reachable from outside.

Local LLMs
ALlama 3, self-hostedConfidential
BMixtral, self-hostedSecret
CGemma, self-hostedConfidential
Databases
ACustomer recordsConfidential
BPayroll & financeSecret
Knowledge bases
AHR & policy docsConfidential
BLegal & contractsSecret
Essential Deck Classification decides what's allowed to cross

Outside

Public internet

Only Public- and Internal-level requests are ever allowed through — and every crossing is logged.

Public LLMs
AChatGPT (OpenAI)Public
BClaude (Anthropic)Public
CKimi (Moonshot AI)Public
External signals
AMarket pricing feedPublic
BCompetitor news monitorInternal
Inside your network
Crosses the gate — classification-gated, logged
Sensitivity scale:
Public Internal
Gate
Confidential Secret

Built for governed, data-sensitive organizations

Financial services Healthcare Public sector Regulated enterprise Internal platform teams
The problem

LLMs are already inside your company. Governance isn't.

Employees are pasting confidential data into chat windows and generating SQL against production databases with no clearance model, no approval trail, and no idea which provider the data ultimately lands on.

01

No clearance model

Anyone with a login can reach any connected database, knowledge base, or LLM channel — regardless of department or classification level.

02

No approval trail

A new database connection or LLM channel goes live the moment someone configures it, with no record of who signed off, or when.

03

No usage visibility

No unified log of what was queried, what was retrieved, what it cost, or which conversations should have been flagged for review.

How it works

One control plane, two applications

An admin app for configuring and approving infrastructure. A user app for chatting, querying, and building dashboards — never outside the boundaries governance has approved.

Configure

IT and governance staff register database connections, LLM providers/channels, knowledge bases, departments, clearances, agents, and webhooks — each tagged with a department and classification level.

Govern

Every one of those nine resource types moves through Draft → Requested → Approved/Rejected → Retirement-requested → Retired, with a full polymorphic audit trail of every transition.

Use

Employees chat, run governed data queries, retrieve from knowledge bases, and generate live dashboards — always scoped to what they're individually cleared for.

See it in action

From governed chat to a live dashboard, and the admin view behind it

What employees see when they chat and build dashboards, and what governance teams see when they map how everything connects.

Chat · Support department
Why did refund requests spike in the EU region last week?
EU refund requests rose 34% week-over-week, concentrated in the DE and FR storefronts — mostly late-delivery claims tied to the carrier switch on the 12th. Scoped to Support · Internal clearance
Ask about your data...

Governed chat

Every answer is generated only from what the asking user is cleared to see — with the clearance and department shown inline, not hidden in a log.

Dashboard · Marketing department
Build me a dashboard of weekly signups by channel.
Here's your live dashboard, queried against the Marketing warehouse connection and scoped to your clearance:
2,140
SIGNUPS (7D)
+18%
VS PRIOR WEEK
Organic
TOP CHANNEL
MonTueWedThuFriSatSun

Chat-generated live dashboards

Describe what you want and Essential Deck drafts a dashboard spec, queries it live, and keeps it clearance-checked for every future viewer — not just the person who asked.

Admin · Topology
Dept Orchestrator Agent Channel A Channel B Channel C GPT-4o Claude Llama
Approved Requested Rejected Shape = resource type · Fill = classification · Border = approval status

Topology view

Governance and platform teams see the full graph — department, orchestration, agents, channels, and providers — colored by classification and approval state, clickable straight through to each record.

What you get

Everything a governance team needs, everything a user expects

Nine capabilities that together turn "we have an LLM chatbot" into "we have a governed AI platform."

Department-scoped clearance

Every resource carries a department and classification level. Users only reach what they're cleared for — and clearances themselves expire and are approval-gated.

Real approval workflow

Draft → Requested → Approved/Rejected → Retirement-requested → Retired across all eight governed resource types, with a complete audit trail of who did what, when.

Governed chat over your data

Chat routes to whichever LLM channel is orchestrated for the user's department and use case — Chat, Data Query, Knowledge Base Query, or Dashboard. Admin-registered relationships between tables (auto-detected from real foreign keys, or entered by hand) keep generated SQL joining tables correctly instead of the model guessing.

LLM-generated live dashboards

Describe what you want in chat and the system builds and queries a dashboard spec against accessible connections — shareable read-only, clearance-checked for every viewer.

Autonomous agents

Schedule- or webhook-triggered work runs under its own service-account identity, keeping cost, quota, and audit trail separate from the human who configured it — every run lands in an Agent runs log with its outcome.

Cost & quota control

Per-user daily/weekly/monthly token quotas enforced automatically, plus a live usage/cost log and a 30-day spend rollup for chargeback.

Full audit & monitoring surface

Separate logs for general audit, database query, knowledge-base retrieval, LLM usage/cost, webhook deliveries, application errors, and flagged conversation alerts.

Secrets encrypted at rest

Connection strings and provider auth tokens are encrypted at rest and masked in the UI — not just access-controlled — with a written IT general-controls guide.

Governance workflow

Nothing goes live without a paper trail

Database connections, LLM providers and channels, knowledge bases, agents, webhooks, clearances, and preset queries all move through the same approval state machine — so "who approved this and when" is a lookup, not an investigation.

  • Nine governed resource types share one transition model: submit, redirect, approve, reject, request retirement.
  • Polymorphic audit log captures every transition against every resource type in one queryable trail.
  • Clearance grants are approval-gated, not a toggle an admin flips — and they expire on their own schedule.
  • Approval designators pin exactly who approves each resource type per department — no ad hoc assignee picking, and nothing can be submitted into a scope with no configured approver.
Approval queue — Finance department
REQUESTED LLM Channel — Remote GPT provider
2m ago
APPROVED Clearance — J. Alvarez, Confidential
41m ago
APPROVED DB Connection — Snowflake (revenue)
3h ago
REJECTED Webhook — external CRM sync
Yesterday
RETIREMENT REQUESTED Agent — legacy nightly digest
2 days ago
Cost & usage

Know what it costs before finance asks

Every LLM call is metered against per-user quotas and logged for chargeback, so platform owners can answer "what did this department spend on AI last month" without pulling provider invoices.

  • Daily / weekly / monthly quotas enforced automatically per user, per provider.
  • Live usage/cost log for chargeback and budget conversations.
  • 30-day spend rollup on the dashboard, no export required.
Usage — last 30 days
$4,215
TOTAL SPEND
18.2M
TOKENS USED
96%
UNDER QUOTA
Marketing — Chat channel
$980
Finance — Data Query
$1,410
Support — Knowledge Base Query
$865
Ops — Nightly digest agent
$960
Security & compliance

Built with governance teams in the room

Secrets handling, an explicit shared-responsibility model, and a written controls guide — so IT security can evaluate this the same way they'd evaluate any other governed system.

Encryption at rest

Provider auth tokens and database connection strings are encrypted at rest and masked in the UI, not merely access-controlled.

IT general controls guide

A written document distinguishing what the app enforces from what remains the customer's infrastructure responsibility — network segmentation, MFA/SSO, DR/backup, vendor risk review.

Provider & database agnostic

MySQL, Postgres, ClickHouse, Snowflake, BigQuery, Databricks, DuckDB and more via SQLAlchemy — any local or remote LLM behind a generic provider abstraction — and a choice of vector store (embedded LanceDB, pgvector, or a Qdrant server) behind that same pattern.

SSO — SAML or OIDC

Hand off authentication to your existing identity provider (Okta, Azure AD, Keycloak, ADFS, and others) for the user portal, while admin login stays a deliberate, separately-authenticated step.

PII-aware column masking

Tag data-dictionary columns Open, Mask, or Redact, enforced at the SQL level, not left to the model's discretion. Masked values reach the LLM as stable per-conversation tokens — never the raw value — and are only swapped back for the human reading the reply.

Self-hosted, your infrastructure

Deploys inside your own environment, per customer — your data and secrets never leave infrastructure you control unless you choose a remote LLM channel.

Conversation monitoring

Conversations are flagged for governance review, alongside dedicated logs for queries, retrieval, webhook deliveries, and application errors.

Explicit remote-routing decisions

Routing a department's channel to a remote LLM provider is a visible, approvable decision — never an implicit default.

Get started

See your data, your LLMs, and your governance rules in one system

Tell us a bit about your team and we'll set up a walkthrough with your own use cases — departments, data sources, and the approval policy you'd actually run.

We'll only use this to reach out about your demo.